Out-of-bounds read in cURL and libcurl - CVE-2017-1000099

 

Out-of-bounds read in cURL and libcurl - CVE-2017-1000099

Published: August 15, 2017


Vulnerability identifier: #VU7882
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000099
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information.

The weakness exists due to out-of bounds read. A local attacker can load a specially crafted 'file://' URL to cause the curl application to return data from system memory.

Successful exploitation of the vulnerability results in information disclosure.

Affected software

cURL
libcurl
Arch Linux
Gentoo Linux
Amazon Linux AMI
Slackware Linux
Fedora
curl (Alpine package)
curl

How to mitigate CVE-2017-1000099

Update to version 7.55.0.

curl (Alpine package) - update to 7.55.0-r0
curl - addressed in versions 7.51.0-9.fc25, 7.53.1-10.fc26

External References

Related Security Bulletins